OpenAI subpoenaed by Alabama attorney general over Hugging Face hack

By Hadas Gold, CNN
(CNN) — Alabama’s attorney general on Monday subpoenaed OpenAI for more information related to its AI agents autonomously hacking into another company’s servers in July.
The subpoena is part of an investigation into whether OpenAI’s practices “violated Alabama’s consumer protection laws” and pose a risk to Alabama citizens, the attorney general’s office said in a statement.
Last month, OpenAI disclosed that during a test of its AI models’ capabilities on cybersecurity, the agents autonomously escaped the lab environment and hacked Hugging Face, an online platform for AI models and data sets, to obtain the answer to the test.
“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical. Our investigation seeks to uncover the facts and address hard truths about the threats companies and consumers are facing from rogue AI,” Attorney General Steve Marshall said in the statement.
OpenAI called the Hugging Face hack “unprecedented,” and the company’s president, Greg Brockman, said the incident “showed that we underestimated the real-world cyber capabilities of our AI models.” OpenAI halted some of its AI model training and is hardening its testing, monitoring and training protocols following the incident.
“The Hugging Face incident marked an important moment for AI safety and we are conducting a thorough review along with external advisors,” an OpenAI spokesperson told CNN on Monday. “Once the review is complete, we will share a technical report with relevant government authorities and publish our findings publicly.”
Monday’s subpoena calls for OpenAI to document its safety protocols and model behavior records as well as ascertain all damages caused by the hack, in addition to other information.
Alabama, along with 14 other Republican states’ attorneys general, sent a letter earlier this month to OpenAI demanding the company preserve information and documents related to the Hugging Face hack.
The problem of autonomous agents going rogue isn’t limited to OpenAI — Meta and Anthropic also disclosed their own systems took unsanctioned actions during cybersecurity tests, a wake-up call for the AI and cybersecurity industry.
OpenAI faces a litany of lawsuits and investigations by various states. This includes cases related to its engagement algorithms, handling of consumer and health data, model “sycophancy,” and its marketing strategies directed at minors and senior citizens. In June, Florida became the first state to sue OpenAI and its CEO, Sam Altman, alleging the company knows ChatGPT is not safe for minors.
The-CNN-Wire
™ & © 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.